# Stop delivering a receiving domain's mail

`DELETE /v1/inbound/domains/{domain}/webhook`

- Authentication: required (Bearer token)
- Required scope: `api.inbound.manage`

Clears the webhook, the signing secret, the allow-list and the postures,
and re-publishes the routing without this domain's delivery target.

Non-destructive, and the difference from `DELETE /v1/inbound/domains/{domain}`
is the point: this leaves the domain, so putting the webhook back with a
`PUT` undoes it. Mail keeps arriving and keeps landing in your bucket
throughout; it stops being delivered, and is recorded as
`unknown_domain`.

The secret does not come back with the webhook — a re-save mints a new
one — which is the one part that is not restored, and it is a credential
rather than data.

## Path parameters

- `domain` (string, required) — The receiving domain, by NAME (`in.acme.com`). A UUID is also accepted. Matched case-insensitively, and scoped to the calling org — a domain belonging to another org is a 404, never a 403.

## Example request

```bash
curl -X DELETE 'https://api.sendops.dev/v1/inbound/domains/string/webhook' \
  -H "Authorization: Bearer $SENDOPS_API_KEY"
```

## Responses

### 200 — The receiving domain, with no webhook

Content type: `application/json`

```json
{
  "domain": "string",
  "id": "00000000-0000-0000-0000-000000000000",
  "status": "pending_dns",
  "last_error": "string",
  "region": "string",
  "cross_region": true,
  "mx_verified_at": "2026-05-17T20:00:00Z",
  "identity_verified_at": "2026-05-17T20:00:00Z",
  "records": [
    {
      "type": "MX",
      "name": "string",
      "value": "string",
      "verified": true
    }
  ],
  "webhook": {
    "url": "https://example.com",
    "allow_patterns": [
      "string"
    ],
    "spam_posture": "tag",
    "virus_posture": "tag",
    "status": "unset",
    "error": "string",
    "published_at": "2026-05-17T20:00:00Z"
  },
  "created_at": "2026-05-17T20:00:00Z"
}
```

### 401 — Missing, malformed, or unknown API key

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```

### 403 — Either the credential lacks the required scope (`code: invalid_scope`), or it is bound to the `test` environment and this operation is irreversible (`code: test_environment_forbidden`). Branch on `code`: the first is fixed by granting the scope, the second only by using a live credential. See the "Live and test credentials" section of the API description.

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```

### 404 — Resource not found

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```

### 429 — Per-org rate limit exceeded

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```

### 500 — Unexpected server-side failure. The `code` is `internal_error`. The
`request_id` field can be quoted to SendOps support to investigate.

Content type: `application/problem+json`

```json
{
  "type": "https://example.com",
  "title": "string",
  "status": 0,
  "detail": "string",
  "code": "invalid_key",
  "request_id": "string",
  "retry_after": 0,
  "retention_days": 0,
  "scope": "string",
  "resource": "string",
  "errors": [
    {
      "field": "string",
      "reason": "string"
    }
  ],
  "attribute_id": "00000000-0000-0000-0000-000000000000",
  "content_hash": "string",
  "differs": [
    "string"
  ]
}
```
